Legal · Zimam Health
Zimam Health privacy policy
Last updated: August 30, 2026
Zimam Health lets you view records shared by participating hospitals and manage appointments from one signed-in app. This page explains which data the app handles and what happens to it.
Information handled by Zimam Health
The app and Health service handle the information needed to identify you, connect the right hospital records, and provide the features you request.
- Zimam ID information, including your account identifier, email address, and display name.
- Identity-linking information, including your national ID and a one-time code issued by a participating hospital.
- Medical records supplied by hospitals linked to you, such as encounters, laboratory results, medications, and imaging reports.
- Appointment information, including availability, booking requests, status, and cancellation requests.
- An Expo push token and device platform when you enable notifications.
- Security and access records showing which authenticated account accessed a type of health information and when.
Where the information comes from
You provide your sign-in and identity-linking details. Participating hospitals provide the medical and appointment information that they hold about you. Zimam ID provides the authenticated account information used to sign you in.
How we use it
We use this information to:
- Authenticate your account and link it to the correct patient record.
- Show records from hospitals connected to that patient record.
- Search appointment availability and send booking or cancellation requests to the relevant hospital.
- Send service notifications and refresh the relevant screen when you open one.
- Protect the service, investigate problems, and keep an access audit for health information.
Notifications
Zimam Health uses Expo Push Notifications and Google Firebase Cloud Messaging to deliver Android notifications. The notification service receives a device token and neutral delivery text. Lock-screen messages do not include diagnoses, test results, medication names, national IDs, or other medical details. The app retrieves details from Zimam Health only after authenticated access.
Sharing and service providers
Participating hospitals remain the source of their medical records and receive appointment requests directed to them. Zimam operates the Health API, database, and Keycloak identity service on infrastructure managed for Zimam. Expo and Google process the limited device and notification data needed to deliver pushes.
We do not sell health data or account data. Zimam Health has no advertising SDK and no third-party analytics or crash-reporting SDK.
Storage and account security
The app stores authentication tokens in the operating system's secure credential storage. Health records are requested from the Health service after sign-in rather than placed in notification payloads. Access to patient surfaces is checked against the current account-to-patient link on every request.
No internet service can promise absolute security. If you believe someone has accessed your account without permission, contact us promptly.
Deletion, retention, and hospital records
Deleting your Zimam Health account removes the link between your Zimam ID and the patient record, deletes registered push tokens, and pseudonymizes your account identifier in retained security audit entries. It does not delete your shared Zimam ID, which may be used for another Zimam product.
Medical records and appointment history supplied by a hospital remain part of that hospital's records and the provider-linked Health mirror. Requests to correct or erase a hospital medical record must be directed to the hospital that created it. Read the Zimam Health account deletion guide for the steps and off-app request option.
Zimam Health account deletion guideYour choices
You can decline notification permission and continue using the app without push alerts. You can delete the Health link from inside the app. For questions, access requests, or a request concerning the shared Zimam ID, email privacy@zimamsys.com.
Children and dependants
A hospital may hold records for a minor or dependant under the rules that apply to that provider. A parent, guardian, or authorized representative should contact the relevant hospital and privacy@zimamsys.com before attempting to manage another person's account or records.
Changes and contact
We may update this policy when the app or its data handling changes. The revised date will appear at the top of this page. Questions or concerns can be sent to privacy@zimamsys.com.